Oracle · Oracle Database Server · CVE-2024-21066
**Name of the Vulnerable Software and Affected Versions**
Oracle Database Server versions 19.3 through 19.22
Oracle Database Server versions 21.3 through 21.13
**Description**
The issue is related to the RDBMS component of Oracle Database Server, allowing a high-privileged attacker with authenticated user privilege to compromise the RDBMS. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access to critical data or complete access to all RDBMS accessible data.
**Recommendations**
For Oracle Database Server versions 19.3 through 19.22, update to a version outside of this range to mitigate the risk.
For Oracle Database Server versions 21.3 through 21.13, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the RDBMS component until a patch is available.